After upgrading to Data Loss Prevention (DLP) 25.1, log entries in the Enforce Server or Endpoint Prevent Server continue to reference the 16.0 version directory for incidentblobdata or compatibility thresholds. This occurs even when the system is otherwise functional on version 25.1.
Symptoms The SymantecDLPDetector.log or IncidentPersister.log contains entries similar to:
Source: com.vontu.util.config.SystemProperties.setSystemProperties Message: System Properties: com.symantec.dlp.incident.blob.externalization.dir=####/ProgramData/Symantec/DataLossPrevention/EnforceServer/16.0.00000/incidentblobdata
The MonitorController.properties file may also contain:
com.vontu.monitor.controller.endpointsystemevent.checkCompatibility.warningAgents.threshold = 16.0.00000
During the upgrade process, certain configuration files retain the hardcoded paths or version thresholds from the previous installation.
Update the configuration files to reference the correct 25.1 paths:
C:\Program Files\Symantec\DataLossPrevention\EnforceServer\25.1\Protect\config\ (or equivalent path for Detection).Protect.properties in a text editor.com.symantec.dlp.incident.blob.externalization.dir = ####/ProgramData/Symantec/DataLossPrevention/EnforceServer/16.0.00000/incidentblobdataPlease note:
If externalization is not being used the hard coded path is irrelevant.
If externalization is being used, we recommend you create a directory outside of the installation folder, preferably on a seperate drive with plenty of space.
For further assistance with log retrieval, see . To speak with a support engineer, see .